Public exploitation

Exploit catalog

Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.

75,589cataloged exploits
34,508CVEs with public exploitation
24,695lab-tested
21,554 exploits
Referência
CVE-2008-4601
Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbi
23RISK
open
Referência
CVE-2010-2316
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to i
23RISK
open
Referência
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RISK
open
Referência
CVE-2018-7449
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RISK
open
Referência
CVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RISK
open
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5596remotewindows
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RISK
open
ReferênciaVexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
CVE-2006-6866webappsphp
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RISK
open
Referência
CVE-2021-24719
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RISK
open
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RISK
open
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RISK
open
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RISK
open
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6497webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RISK
open
ReferênciaVexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
CVE-2008-3851webappsphp
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RISK
open
ReferênciaVexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
CVE-2009-0383webappsphp
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RISK
open
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISK
open
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RISK
open
Referência
CVE-2009-3042
SQL injection vulnerability in machine.php in Open Computer and Software (OCS) Inventory NG 1.02.1 allows remote attacke
23RISK
open
Referência
CVE-2006-5629
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arb
23RISK
open
Referência
CVE-2009-3362
PHP remote file inclusion vulnerability in printnews.php3 in SZNews 2.7 allows remote attackers to execute arbitrary PHP
23RISK
open
Referência
CVE-2012-0902
AirTies Air 4450 1.1.2.18 allows remote attackers to cause a denial of service (reboot) via a direct request to cgi-bin/
23RISK
open
Referência
CVE-2017-6089
SQL injection vulnerability in PhpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via
23RISK
open
Referência
CVE-2013-3728
Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissio
23RISK
open
Referência
CVE-2016-3986
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISK
open
Referência
CVE-2011-4670
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RISK
open
Referência
CVE-2011-4670
Multiple cross-site scripting (XSS) vulnerabilities in vTiger CRM 5.2.1 and earlier allow remote attackers to inject arb
23RISK
open
Referência
CVE-2018-11508
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitiv
23RISK
open
Referência
CVE-2010-4792
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrar
23RISK
open
Referência
CVE-2010-5042
Cross-site scripting (XSS) vulnerability in the DJ-ArtGallery (com_djartgallery) component 0.9.1 for Joomla! allows remo
23RISK
open
Referência
CVE-2018-1002001
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability re
23RISK
open
Referência
CVE-2018-12234
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied
23RISK
open
previouspage 217 / 719next

We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.